As cited
Copy frozen at (site build).
ransomware
What's Trending: Top Cyber Attacker Techniques, March - May 2026
A threat report covering March through May 2026 finds that ClickFix (a social engineering delivery technique) has become the dominant initial access method, driving 14.9% of spearphishing attacks and nearly 28% of defense-evasion activity while reaching macOS for the first time. The malware leaderboard underwent near-complete turnover for a second consecutive period, with defenders advised to focus on attacker behavior patterns rather than malware family names. Ransomware operators like Qilin continue exploiting unpatched internet-facing firewalls and VPNs using a consistent playbook.
Why it matters: Security teams need to shift detection focus from malware names to behavioral patterns, especially ClickFix social engineering and exploitation of unpatched edge infrastructure, since the report shows attackers are rotating malware families rapidly while techniques remain consistent, and AI is accelerating social engineering at scale.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
What's Trending: Top Cyber Attacker Techniques, March - May 2026
A threat report covering March through May 2026 identifies ClickFix as the dominant attack delivery method, now reaching macOS for the first time, while malware families continue to rotate rapidly on the threat leaderboard. The analysis finds that ransomware operators converge on similar tactics: exploiting unpatched internet-facing firewalls, VPNs, and Cloudflare tunnels rather than relying on specific malware families or tools. Defenders should prioritize behavior-based detection, maintain ClickFix detection across platforms, and rapidly patch edge infrastructure.
Why it matters: Practitioners must shift from malware-name tracking to behavior detection because delivery methods and tactics remain consistent even as malware families change; threat leaders should immediately patch internet-facing firewalls and VPNs and deploy ClickFix detection on both Windows and macOS to block the leading initial access vector.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
What's Trending: Top Cyber Attacker Techniques, March - May 2026
A threat report covering March through May 2026 identifies ClickFix as the dominant attack delivery method, now reaching macOS for the first time, while malware families continue to rotate rapidly on the threat leaderboard. The analysis finds that ransomware operators converge on similar tactics: exploiting unpatched internet-facing firewalls, VPNs, and Cloudflare tunnels rather than relying on specific malware families or tools. Defenders should prioritize behavior-based detection, maintain ClickFix detection across platforms, and rapidly patch edge infrastructure.
Why it matters: Practitioners must shift from malware-name tracking to behavior detection because delivery methods and tactics remain consistent even as malware families change; threat leaders should immediately patch internet-facing firewalls and VPNs and deploy ClickFix detection on both Windows and macOS to block the leading initial access vector.
- Source published
- First seen by Cybersecurity Tracker